Middleware-Based Redundancy for Process Control Failover

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current process control systems lack flexible redundancy options, particularly in software and combined hardware-software redundancy, which limits their ability to provide different availability levels for various system parts, increasing costs and hardware requirements.

Innovation Solution

A network-centric process control system with middleware services enabling flexible redundancy configurations for controllers, gateways, and devices, allowing for hardware and software redundancy based on multiplicated units, spare capacity, and edge/cloud resources, with signal exchange and synchronization mechanisms to ensure seamless failover.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If hardware redundancy based on multiplicated hardware units is used, then system availability is improved, but hardware cost and system complexity increase

Engineering Contradiction:
Improvesystem availabilityVSAvoidhardware complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments redundancy functionality into virtualization layer and hardware layer, allowing independent management of computational resources. Virtual machines can be migrated between physical hosts, separating the redundancy function from specific hardware units and reducing overall system complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements universal hardware platforms that can host multiple virtual machines with different redundancy configurations. A single physical host can provide redundancy services to multiple controllers simultaneously, making hardware units multi-functional and reducing the need for dedicated redundant hardware for each controller.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If software redundancy is added to hardware redundant controllers, then availability is improved, but system complexity and cost increase

Engineering Contradiction:
ImproveavailabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges hardware redundancy and software redundancy into a unified virtualization-based redundancy system. Virtual machines encapsulate both hardware abstraction and software control logic, combining multiple redundancy mechanisms into a single integrated platform that manages both hardware and software failure scenarios simultaneously.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If the same availability level is selected for all system parts, then reliability is improved, but hardware cost increases

Engineering Contradiction:
Improvesystem reliabilityVSAvoidhardware cost
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The system applies different redundancy quality levels to different controllers based on their criticality. Critical controllers receive high-availability configurations with full redundancy and fast failover, while non-critical controllers use simplified configurations. This local differentiation of quality levels optimizes hardware resource allocation and reduces overall system cost while maintaining necessary reliability.

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP3702857B1Redundancy in a network centric process control system
Publication Date: 2024.07.24 ABB (SCHWEIZ) AG
  • EP3702857B1 patent drawingFigure 1~2
  • EP3702857B1 patent drawingFigure 3~4a
  • EP3702857B1 patent drawingFigure 4b

AI summary

Embodiments presented herein relate to a method for providing redundancy in a network centric process control system, where at least one node comprises at least one control service as well as at least one middleware service for communicating in the process control system, where the control service and middleware service is each a separate executable running in a separate operating system process provided by a real time operating system thereof, wherein a first control service in a first node communicating via a first middleware service and implementing a first control function acts as an active control service for the first control function and a second control service communicating via a second middleware service and implementing the first control function acts as a standby control service for the first control function, the method comprising performing (S102), by the first control service, the first control function through subscribing (S102a), via the first middleware service (70), to input process data of the first control function and publishing, (S102b), via the first middleware service (70), output process data of the first control function (A), synchronizing (S104) the first control service with the second control service, and taking over (S108), by the second control service based on a determination that a fault has occurred in the first node (50), the role of active control service, the taking over comprising publishing (S108b), by the second control service (78) via a second middleware service (108) provided for the second control service (78), the output process data of the first control function based on a subscription of the second control service (78) to the input process data.